CVE-2024-23369
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-23369 is a newly disclosed memory corruption vulnerability. It affects the handling of HLOS (Hypervisor-Based Local Out-of-Band Services) input for FRS/UDS (Flexible Real-Time Transport Protocol for Automotive Diagnostic and Communications) request/response buffers. An attacker who can provide invalid length data to the HLOS may successfully corrupt the memory of the affected system, potentially leading to unintended execution of code or a denial-of-service condition. Systems utilizing FRS/UDS protocols and interacting with HLOS are at risk and should be promptly patched to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.